Launch coins signed once for all.
Every coin is signed by a one-time, hash-based key derived from your wallet. Nothing but SHA-256 stands behind it, so there is no curve for a quantum computer to break, and a stranger can check any signature holding the root, the message, and nothing else of yours.
Launching works. The launch page calls pump.fun’s create_v2 on mainnet and spends real SOL. This project has no coin of its own yet. What is not deployed is the on-chain verifier: the attestation is checkable by anyone holding the algorithm, and not yet by a Solana program.
Coins launched here
Quantum means a one-time key signed the record. Standard means nothing did.
reading /api/launches…
What a verifier actually does
- 01 sign
σ[i] = H^d[i](sk[i])each of the 67 chains is walked d[i] steps, where d is the digest in 4-bit pieces plus 3 checksum pieces - 02 recover
pk[i] = H^(15−d[i])(σ[i])the verifier walks the rest of the way and sees where it lands, holding no secret at any point - 03 commit
leaf = H(pk[0] ‖ … ‖ pk[66])the one-time key is squeezed into a single leaf of the tree - 04 climb
root =? H(…H(leaf ‖ a[0])… ‖ a[7])8 siblings carry the leaf to the root that was published once
Between 45 and 990 hashes, depending on the digest. No curve, no pairing, no trusted setup, and nothing that a larger quantum computer makes easier than Grover already does.
What this rests on
Each line is a thing the rest of this site claims, with the thing that would make it false printed next to it. Neither can be rendered without the other.
- Only SHA-256 stands behind a key here
Grover's algorithm halves that, so the honest figure is about 128 bits against a quantum adversary, not 256.
- Each key signs exactly once
Two signatures under one key leak enough to forge a third. The identity has 256 keys and the page prints how many are left.
- A program will verify the signature on chain
None is deployed today. When one is, whoever holds its upgrade authority can replace it, so until that authority is set to none this page names the key that can.
- A root can be anchored on Solana
Anchoring is a separate, optional transaction. An identity that has not been anchored says so, and no page counts it as if it had.
What does not exist yet
- Domain
- ephapax.fun, registered 2026-10-11 and serving this build
- On-chain verifier
- no program is deployed, so no page here says one verifies anything
- The coin
- none. $EPHA is what will be asked for, not what has been read
- Launching
- works. The launch page calls pump.fun's create_v2 and spends real SOL; what is missing above is the verifier, not the launch
- X account
- @Ephapax_, id 2109215853841715200, read back 2026-10-11
@Ephapax_ is ours. @Ephapax, without the underscore, is a different account with id 1372971042: a real account from long before this project, now displaying the same name. Both return 200 and both display the same name, so the id is the only thing that tells them apart and it is printed here rather than left to be noticed.
And what does, counted now
reading the store… these numbers are not rendered until they have been read, because a placeholder zero is a figure.
the rail's coin is written as a phrase rather than a symbol, because a ticker is decoded off a mint and this one has no mint. Every signature binds itself to ephapax/wots-sha256/w16/h8/v1, over a 32-byte digest walked at most 15 steps per chain.